CVE-2026-91078
TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.
| Vendor | unknown |
| Product | tillkit |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown tillkit
Be the first to know when new unknown vulnerabilities affecting unknown tillkit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / TillKit
0 < 1.0.5
References
Credits
Pedro Pinho WPScan